Senior Application Security Engineer

2 weeks ago


North Sydney Council, Australia TPG Telecom Full time

We've only just begun, but what a beginning. In a once in a generation moment, we've brought together powerful brands to create one united force. TPG Telecom has a powerhouse of brands which include Vodafone, TPG, iiNet, Internode, Lebara, AAPT and felix. The latest technology and brave thinking let us connect our people and communities. You could play a role in that. A big one. We invite you to bring your boldness and stand out. You are empowered. Opportunities are plenty for those ready to accept the challenge.

This opportunity

We are in pursuit of a dedicated Senior Application Security Engineer to be a key player in our Security Assurance Team. In this role, you will blend technical acumen with an empathetic approach, ensuring our software development processes are both sophisticated and secure. Working together with our Red-team and wielding tools like static code analysis and Dynamic Application Security Testing (DAST), you will be the guardian of our code, ensuring it meets the zenith of security standards.

Successful people in Security maintain close relationships with colleagues across TPG Telecom, foster friendly working environments, and demonstrate a willingness to ask questions. You will achieve this through empathy and integrity, as these qualities are important to the role. At TPG, we value diversity and encourage innovation. We recognise that mistakes are a part of growth, and we appreciate individuals who are willing to explore innovative approaches to old problems.

Responsibilities

Execute comprehensive reviews of application codes, unearthing and addressing potential security risks. Harness tools like static code analysis and DAST to provide detailed and thorough code evaluations. Collaborate seamlessly with our Red team, integrating their insights to strengthen our digital defences. Ensure unwavering adherence to our Software Security Development Life Cycle (SSDLC). Educate and guide development teams, championing a culture of security-conscious development and continuous growth. Maintain an up-to-date understanding of contemporary security trends, vulnerabilities, and protective measures. Apply a nuanced understanding of risk, integrating it into evaluations to prioritize and address potential vulnerabilities effectively. Foster a nurturing environment that promotes mutual respect, continuous learning, and collaboration.

Key Tasks and Expectations

Static Code Analysis: Use state-of-the-art tools to perform a detailed static analysis of application codes, ensuring that potential vulnerabilities are identified and addressed. Dynamic Application Security Testing (DAST): Execute real-time security testing on applications in their running state, highlighting live potential security threats IAST: Utilise interactive application security testing (IAST) tools to combine dynamic and runtime analysis. Threat Modelling: Lead sessions to identify, quantify, and address security threats at various stages of the development process. Code Reviews: Collaborate with development teams, conducting comprehensive code reviews to pinpoint and address security-related issues. Risk Assessment: Evaluate security findings and understand them in the context of business risk, helping prioritise security efforts accordingly. Collaboration with Red Team: Work closely with the Red Team to understand potential attack vectors, utilizing their findings to fortify the security posture of applications under development. SSDLC Adherence: Ensure that the Software Security Development Life Cycle (SSDLC) processes are strictly followed throughout the development phase, ensuring security is embedded at every stage. Security Training: Offer guidance, training sessions, and workshops to development teams, emphasizing the importance of security best practices and fostering a culture of security-conscious development. Continuous Learning: Stay updated with the latest trends in security vulnerabilities, defence mechanisms, and best practices in the industry. Feedback Loop: Create a mechanism for timely feedback to developers on security-related issues, ensuring that vulnerabilities are addressed swiftly. Integration of Security Tools: Ensure that appropriate security tools are integrated into the CI/CD pipeline, enabling automated checks and early detection of potential threats. Documentation: Maintain clear and comprehensive documentation of findings, recommendations, and actions taken, ensuring that all stakeholders are informed and that there is a clear record for future reference.

Knowledge and experience

Your experience within the digital assurance area in the retail and/or telecommunications sectors will be highly valued. We need a keen eye for detail, an ability to understand complex IT systems, and a talent for simplifying complexities. Most importantly, we seek someone excited about their role, friendly, empathetic, and ready to collaborate.

Benefits and perks

Flexible hybrid way of working (from home and office) 'Stay Connected Mobile' – Access to a free mobile plan 'Stay Connected NBN' – Access to a free NBN 100 plan 'Your Leave' - an additional 4 days of leave to be used whenever you like - every year Access to TPG Learning Hub platform and internal development opportunities Access to Corporate Partner Discounts

Bolder and better together

Don't meet every single requirement? We're ok with that. Studies have shown that women and those of underrepresented groups are less likely to apply for roles unless they meet every single criteria. At TPG Telecom we recognise that what may make you different, makes the difference

We're all about enabling every individual to be their authentic selves and creating a place where everybody belongs. If you are excited about this role, but your experience doesn't align perfectly with every qualification in the job description, we encourage you to APPLY NOW regardless.



  • North Sydney, Australia TPG Telecom Full time

    We’ve only just begun, but what a beginning. In a once in a generation moment, we’ve brought together powerful brands to create one united force. TPG Telecom has a powerhouse of brands which include Vodafone, TPG, iiNet, Internode, Lebara, AAPT and felix. The latest technology and brave thinking let us connect our people and communities. You could play...


  • North Sydney, Australia TPG Telecom Full time

    We’ve only just begun, but what a beginning. In a once in a generation moment, we’ve brought together powerful brands to create one united force. TPG Telecom has a powerhouse of brands which include Vodafone, TPG, iiNet, Internode, Lebara, AAPT and felix. The latest technology and brave thinking let us connect our people and communities. You could play...


  • North Sydney Council, Australia Nine Full time

    Cyber Security Applications Engineer - Identity Nine is Australia's largest locally owned media company – the home of Australia's most trusted and loved brands spanning News, Sport, Lifestyle, and Entertainment.We pride ourselves on creating the best content, accessed by consumers when and how they want – across Publishing, Broadcasting and...


  • North Sydney Council, Australia Nine Full time

    Cyber Security Applications Engineer - IdentityNine is Australia's largest locally owned media company – the home of Australia's most trusted and loved brands spanning News, Sport, Lifestyle, and Entertainment. We pride ourselves on creating the best content, accessed by consumers when and how they want – across Publishing, Broadcasting and...


  • North Sydney Council, Australia Nine Entertainment Full time

    Job Description Join our cyber security team and be part of transforming our digital experience and delivering innovative capabilities for Nine. We offer a flexible working environment in a culturally diverse and high functioning team. This is an expansion of the Cyber Security Engineering function, focused on configuring, maintaining, and continuously...


  • North Sydney Council, Australia Firesoft People Full time

    Job Title: Senior Security Engineer for MSPLocation: SydneySalary: $200,000 plus superOur client is a leading IT Service and Infrastructure Solutions Provider. They maintain strong relationships with all major industry-leading IT vendors, offering a comprehensive range of technology services and solutions to perfectly benefit their client's needs and...


  • Sydney, New South Wales, Australia Leracle Full time

    Company Description At Leracle, we are at the forefront of technological innovation, providing cutting-edge solutions that empower businesses to stay secure in an ever-evolving digital landscape.As a leading global provider of advanced cybersecurity services and solutions, we pride ourselves on our commitment to protecting our clients' most valuable assets...


  • Sydney, New South Wales, Australia Leracle Full time

    Company Description At Leracle, we are at the forefront of technological innovation, providing cutting-edge solutions that empower businesses to stay secure in an ever-evolving digital landscape. As a leading global provider of advanced cybersecurity services and solutions, we pride ourselves on our commitment to protecting our clients' most valuable assets...


  • Sydney, New South Wales, Australia Canva Full time

    Join the team redefining how the world experiences design. Hey, g'day, mabuhay, kia ora,你好, hallo, vítejte Thanks for stopping by.We know job hunting can be a little time consuming and you're probably keen to find out what's on offer, so we'll get straight to the point. Where and how you can work Our flagship campus is in Sydney.We also have a campus in...


  • Sydney, New South Wales, Australia Canva Full time

    Join the team redefining how the world experiences design. Hey, g'day, mabuhay, kia ora,你好, hallo, vítejte Thanks for stopping by. We know job hunting can be a little time consuming and you're probably keen to find out what's on offer, so we'll get straight to the point. Where and how you can work Our flagship campus is in Sydney. We also...


  • Sydney, New South Wales, Australia Tal Full time

    TAL We offer flexibility by letting you tailor your cover to suit your individual needs.Quick and easy to apply.Get An Online Quote. View company page From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we're all about.We want to grow with you.Achieve with you.And support you to do your best...


  • North Sydney Council, Australia Nine Entertainment Full time

    Job Description This position is a Cyber Security Support Engineer role managing Netskope DLP and other security engineering tools. This is an important role within the cyber security team and will provide an opportunity for someone to contribute to a significant uplift in Nines security posture. Primary focus will be the uplift of DLP controls, including...


  • Sydney, Australia Charterhouse Full time

    Senior Security Engineer OpportunityAre you passionate about protecting critical data in the fast-paced world of financial services? We're looking for a skilled Senior Security Engineer with 4-8 years of experience, including expertise in cloud environments.Your Role: As a Senior Security Engineer, you'll lead efforts to fortify the companies, computers,...


  • North Sydney Council, Australia Nine Entertainment Full time

    Job Description The Nine Cyber Security team is looking for a strong network focused cyber security engineer. This role plays a crucial role in safeguarding Nine's critical systems and data by overseeing key controls that protect Nine's data and content. The Cyber Security Infrastructure Engineer will be delivering new capabilities such as network...


  • City Of Parramatta Council, Australia CBHS Health Fund Full time

    Security (Information & Communication Technology) CBHS Health Fund Limited is a not-for-profit, restricted access health fund run exclusively for current and former employees of the Commonwealth Bank Group, as well as their immediate families.We are recognised as a leader in customer satisfaction and pride ourselves on truly looking after our members.We are...


  • Sydney, New South Wales, Australia Audinate Full time

    Who we are and what we do Audinate leads the world in networked media with our "Dante" technology which is used extensively in professional audio & video applications, including live events, broadcast, entertainment venues and communication systems.Dante replaces all audio and video connections with a computer network, effortlessly sending video or hundreds...


  • Sydney, New South Wales, Australia Audinate Full time

    Who we are and what we doAudinate leads the world in networked media with our "Dante" technology which is used extensively in professional audio & video applications, including live events, broadcast, entertainment venues and communication systems.Dante replaces all audio and video connections with a computer network, effortlessly sending video or hundreds...


  • North Sydney Council, Australia Nine Full time

    Nine is Australia's largest locally owned media company – the home of Australia's most trusted and loved brands spanning News, Sport, Lifestyle, and Entertainment.We pride ourselves on creating the best content, accessed by consumers when and how they want – across Publishing, Broadcasting and Digital.Nine's assets include the 9 Network, major mastheads...


  • North Sydney Council, Australia Nine Full time

    Nine is Australia's largest locally owned media company – the home of Australia's most trusted and loved brands spanning News, Sport, Lifestyle, and Entertainment. We pride ourselves on creating the best content, accessed by consumers when and how they want – across Publishing, Broadcasting and Digital.Nine's assets include the 9Network, major mastheads...


  • North Sydney, Australia Nine Entertainment Full time

    Job Description Join our cyber security team and be part of transforming our digital experience and delivering innovative capabilities for Nine. We offer a flexible working environment in a culturally diverse and high functioning team.  This is an expansion of the Cyber Security Engineering function, focused on configuring, maintaining, and...